As AI is increasingly used in code reviews and vulnerability hunting, discussions surrounding government network surveillance methods have heated up again. Foreign media reports that if software vulnerabilities are significantly reduced with the assistance of AI, law enforcement and intelligence agencies may find it more difficult to obtain data from target devices using intrusion tools in the future. This could also make the issue of "whether backdoors should be retained" a focal point of contention once more.
Encrypted communication compresses traditional monitoring methods.
Over the past decade or so, applications such as Signal, WhatsApp, and Apple's iMessage have popularized end-to-end encryption, significantly reducing the scope for traditional real-time phone and text message monitoring. At the same time, manufacturers like Apple have gradually made device data encryption the default setting, making it more difficult to directly crack phones protected by strong passwords.
In this context, the government has not completely lost its investigative capabilities. Reports mention that a fragile balance has been established in reality: tech companies generally do not reserve backdoors for the government, while the government invests in purchasing hacking tools, spyware, and zero-day vulnerabilities to gain access to target devices by exploiting security flaws.
Will there be fewer and fewer vulnerabilities?
A professor of cryptography at Johns Hopkins University, Matthew Green, recently suggested that AI could make software “too secure.” His core argument is that large models are discovering vulnerabilities more quickly, and companies may also be able to fix these issues at an unprecedented speed, which means that over time, there will be fewer vulnerabilities that can be exploited.
If this trend continues, the space for governments to rely on vulnerabilities to carry out device intrusions may narrow. Green believes that at that time, some governments may once again request technology companies to provide exceptional access rights, which would essentially mean re-promoting backdoor solutions.
Divergent Views in the Security Industry
Some individuals engaged in vulnerability research and government offensive and defensive operations share this concern. Luna Tong, who has worked at two companies that assist governments in identifying vulnerabilities and developing related tools, stated that the current situation is akin to a "gold rush for vulnerabilities," but this state may not be able to sustain itself in the long term.
Crowdfense The Chief Technology Officer, Paolo Stagno, also stated that no country would voluntarily give up its monitoring capabilities. In his view, it is currently an acceptable practice for governments to rely on real security vulnerabilities to carry out intrusions; however, if these vulnerabilities become increasingly difficult to find, the existing balance may not be able to be maintained.
However, there are also several experts in the security industry who hold the opposite view. They believe that vulnerabilities that are easy to detect will be exposed more quickly, but more complex and valuable vulnerabilities will not disappear as a result. On the contrary, such tools may help vulnerability researchers improve their efficiency.
Backdoor debates may heat up again
The person in charge of cybersecurity at the Electronic Sentinel Foundation, Eva Galperin, believes that the current attackers still have the upper hand. On one hand, AI has improved their ability to find vulnerabilities, and on the other hand, AI's assistance in development may also lead to more new defects. She also pointed out that an increase in vulnerabilities does not mean that manufacturers can quickly fix them, as the actual process of releasing patches is often not that simple.
Luta Security, the founder of a company that has long been involved in handling vulnerability disclosure and patching, stated that we are still some way from achieving a state where mobile phones and laptops are "virtually bug-free." However, she also believes that once vulnerabilities become more apparent, the pressure to reserve backdoors in devices may rise again.
The report suggests that the core of this debate is not merely whether AI will reduce vulnerabilities, but also that once the government loses its current means of intrusion, the old contradiction between privacy protection and law enforcement evidence collection may be pushed to the forefront again.










